4 ms·
What purpose does the expiry date have? There might be something I've missed, but I really can't see one apart from needless complication, which is what makes i
by mkj 1y ago
What purpose does the expiry date have? There might be something I've missed, but I really can't see one apart from needless complication, which is what makes it a mistake. (There are other problems in the UEFI/firmware ecosystem yes, but that doesn't excuse expiry dates)
- jeroenhd 1y agoI don't know if this is why the people behind secure boot adopted this design, but expiry dates make CRLs smaller, at least in theory. If a revoked certificate expires, you don't need to add it to the CRL because trust is invalidated automatically. By rotating root keys occasionally, you can also keep the revocation list for vulnerable bootloaders smaller, as you can remove any vulnerable bootloader when its signatory key expires. With the kind of penny-pinching that happens with NVRAM storage on boards like these, being able to reduce the size of CRLs can make a difference.
- mkj 1y agoHm, I guess that's one point. 15 years worth of accumulated revoked certs is a pretty big list though, not sure how much they win there. Idle thought - wonder if there are perfect hash-like constructions they could use for revoked certificate lists.
- roryirvine 1y agoUEFI's equivalent of the CRL is the "forbidden signature database" (or DBX) - but as far as I can see, it only has 658 entries (the source appears to be https://github.com/microsoft/secureboot_objects/blob/main/PreSignedObjects/DBX/ https://github.com/microsoft/secureboot_objects/blob/main/Pr... ) Another potential use is to facilitate managed deprecation of obsolete crypto functions / protocols / hash suites / etc. That fits pretty well with a 10 year rotation period, and is probably more valuable in the long term than minimising DBX size.